跳到正文
The Decoder· Jonathan Kemper·· 2 小时前AI 评分71

Zenity 研究:一条提示词即可劫持 AWS 账户内全部 AI 智能体

A single prompt was enough to hijack every AI agent in an AWS account, Zenity researchers found

AI 导读

安全公司 Zenity Labs 发现 Amazon Bedrock AgentCore 存在名为 AgentCorruption 的漏洞链,攻击者只需对某个公开可访问的智能体拥有聊天权限,用一条提示词就能接管同一 AWS 账户和区域内所有 AgentCore 智能体,读取私密对话、下载源代码并获取存储的凭证。

来源:The Decoder · the-decoder.com